# ray-claim.website — MALICIOUS — Crypto Drainer (Solana Drainer) > ray-claim.website poses a medium-risk crypto drainer threat impersonating Raydium. Stay alert and verify before interacting with this domain. ## Summary PhishDestroy identifies ray-claim.website as a crypto drainer targeting users of the Raydium platform. This threat is significant because it attempts to steal cryptocurrency assets by impersonating a trusted brand and deploying a Solana drainer kit. The domain was registered on April 27, 2025, via Web Commerce Communications Limited, resolving to IP 172.67.152.202. It appeared on two security blocklists and was detected in one AlienVault OTX pulse. While currently offline, VirusTotal flagged it with seven detections out of ninety-five vendors. Users should avoid interacting with ray-claim.website, especially unsolicited links claiming airdrops. Always verify the official Raydium site URL and never provide private keys or seed phrases to unfamiliar websites. ## Threat Details - Verdict: MALICIOUS — Crypto Drainer (Solana Drainer) - Site status: dead (HTTP 403) - Drainer type: Solana Drainer - Scam type: Airdrop Scam - Kit: Airdrop Scam - Target brand: Raydium - Page title: Raydium | Airdrop ## Domain Intelligence - Registered: 2025-04-27 00:00:00 - Expires: 2026-04-27 00:00:00 - Registrar: Web Commerce Communications Limited - Country: MY - IP: 172.67.152.202 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ariadne.ns.cloudflare.com ignacio.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 7 vendors flagged Vendors: ["alphaMountain.ai", "Bfore.Ai PreCrime", "CRDF", "CyRadar", "Fortinet", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019b8aed-37bc-775a-8454-5346786f238e.png - Cloudflare Radar: https://radar.cloudflare.com/scan/d9a30da8-4b2d-426b-9dff-629194a623e9 - PhishDestroy: https://phishdestroy.io/domain/ray-claim.website/ - LLM endpoint: https://phishdestroy.io/domain/ray-claim.website/llm.txt ## If You Visited This Site 1. Revoke all token approvals immediately (revoke.cash / unrekt.net) 2. Move remaining funds to a new wallet 3. Do not interact with any transactions from this site 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ray-claim.website/ Last updated: 2026-03-19